Junglewise Threat Intelligence

CVE-2026-80914: Linux kernel Bluetooth ISO use-after-free in iso_conn_ready

CVE-2026-80914 · Severity: high · CVSS 8.8 · Published 2026-09-09

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Bluetooth ISO (Isochronous) socket implementation contains a use-after-free vulnerability in the iso_conn_ready() function. This vulnerability allows local attackers to trigger memory corruption by closing a listener socket concurrently with connection setup, causing the kernel to access freed memory and potentially leading to denial of service or code execution.

Technical details

The vulnerability is a use-after-free in net/bluetooth/iso.c within the iso_conn_ready() function. The root cause is a race condition: iso_conn_ready() obtains a socket reference via iso_get_sock(), but then creates a child socket without re-verifying that the parent listener socket is still alive. If the parent socket is closed between the reference acquisition and the lock acquisition, the socket can be freed while still being referenced by the child socket. When the child socket later disconnects and calls iso_chan_del(), it dereferences the dangling parent pointer, triggering a use-after-free. The fix adds a state check after acquiring the socket lock to verify the parent is still in BT_LISTEN state before proceeding.

Affected products

  • Linux Linux kernel All versions with Bluetooth ISO socket support (from commit ccf74f2390d60 onwards)

Timeline

  • 2026-09-09: disclosed: CVE-2026-80914 published on NVD
  • 2026-08-19: patched: Fix committed upstream by Hang Nan (commit 560bef609fa5992745929e8d7d458b9d88dd2830)
  • 2026-09-07: patched: Fix included in stable kernel releases
  • 2026-09-14: other: Additional stable kernel backports completed

References

Related threats